What is CVE-2026-74998?
CVE-2026-74998 affects Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3, where unvalidated CSS proxy responses may lead to information disclosure or XSS via MIME sniffing. Users should update to the latest patched version.
Azərbaycanca: CVE-2026-74998 Roundcube Webmail-in 1.6.18-dən əvvəlki və 1.7.x 1.7.3-dən əvvəlki versiyalarında CSS proxy cavablarının yoxlanılmaması səbəbindən MIME sniffing vasitəsilə məlumat sızması və ya XSS zəifliyinə yol aça bilər. İstifadəçilərə Roundcube-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Roundcube Webmail are affected by CVE-2026-74998?
This vulnerability affects Roundcube Webmail versions before 1.6.18 and 1.7.x versions before 1.7.3.
What risks does CVE-2026-74998 pose to users?
The flaw can lead to information disclosure or XSS via MIME sniffing due to unvalidated CSS proxy responses.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.